Skip to main content

Legal & Privacy

Professional standards for digital stewardship and decision integrity

Terms of Use

Last Updated: March 15, 2026

1. Acceptance of Terms

By accessing and using nitaptech.ca ("the Site"), you acknowledge that you have read, understood, and agree to be bound by these Terms of Use. If you do not agree, please discontinue use of the Site immediately.

2. Informational Purposes Only

The content on this Site is provided for general informational and educational purposes only. While Nitap Technologies strives for accuracy, we make no representations or warranties regarding the completeness, reliability, accuracy, or suitability of any information presented.

You acknowledge that: Cybersecurity threats, regulatory requirements, and technology environments change rapidly. Information on this Site may become outdated, and Nitap Technologies has no obligation to update content unless required by law.

3. Professional Services Disclaimer

CRITICAL: This Site does not establish a professional services relationship between you and Nitap Technologies.

Content on this Site, including but not limited to articles, insights, service descriptions, example deliverables, and technical guidance does NOT constitute:

  • Professional cybersecurity advice tailored to your specific environment
  • Legal, financial, or regulatory compliance advice
  • An assessment of your security posture
  • An assurance of regulatory compliance
  • A recommendation to take or avoid any specific action

For Professional Services: If you require professional cybersecurity, risk management, or compliance services, you must enter into a formal written engagement agreement with Nitap Technologies. Only advice provided under such an agreement constitutes professional services.

3.1 Intellectual Property in Deliverables

While final deliverables (e.g., specific Technology Roadmaps or Audit Checklists) created specifically for a client under a formal agreement may be owned by that client, Nitap Technologies retains all rights, title, and interest in its "Background IP." This includes pre-existing methodologies, templates, prioritization logic, and general cybersecurity frameworks used to produce those deliverables.

4. No Warranties

The Site and all content are provided "as is" and "as available" without warranties of any kind, either express or implied, including but not limited to:

  • Warranties of merchantability or fitness for a particular purpose
  • Warranties that the Site will be uninterrupted, timely, secure, or error-free
  • Warranties regarding the accuracy, reliability, or completeness of content
  • Warranties that defects will be corrected
  • Warranties regarding third-party links or services

5. Limitation of Liability

To the maximum extent permitted by applicable law:

Nitap Technologies, its principal, employees, contractors, and affiliates shall not be liable for any direct, indirect, incidental, consequential, special, punitive, or exemplary damages arising from or related to:

  • Use of or inability to use the Site
  • Reliance on any content, advice, or information on the Site
  • Security breaches, data loss, or unauthorized access
  • Errors, omissions, or inaccuracies in content
  • Third-party conduct or content
  • Any matter relating to the Site or services

This limitation applies even if Nitap Technologies has been advised of the possibility of such damages.

Maximum Liability: In no event shall Nitap Technologies' total aggregate liability exceed the greater of (a) the total fees paid by you to Nitap Technologies in the twelve (12) months preceding the claim, or (b) CAD $100.

Jurisdictional Limitations: Some jurisdictions do not allow the exclusion or limitation of certain warranties or liabilities. In such jurisdictions, our liability is limited to the maximum extent permitted by law.

5.1 Statutory Limitation Period

Consistent with the Limitation of Actions Act of New Brunswick, any claim or legal proceeding arising out of or related to the use of this Site or our services must be commenced within two (2) years from the date the claimant knew, or ought to have known, of the claim.

5.2 Cybersecurity Disclaimer

You acknowledge that no security assessment or vulnerability management service can ensure 100% protection. Nitap Technologies does not warrant that its services or recommendations will prevent all security breaches, "zero-day" exploits, or unauthorized access by sophisticated third parties.

6. Indemnification

You agree to indemnify, defend, and hold harmless Nitap Technologies, its principal, employees, contractors, and affiliates from and against any and all claims, liabilities, damages, losses, costs, expenses (including reasonable legal fees) arising from:

  • Your use or misuse of the Site
  • Your violation of these Terms of Use
  • Your violation of any rights of another party
  • Any content you submit or transmit through the Site

7. Intellectual Property Rights

All content on this Site, including but not limited to text, graphics, logos, images, articles, frameworks, methodologies, and software, is the property of Nitap Technologies or its content suppliers and is protected by Canadian and international copyright, trademark, and other intellectual property laws.

You may:

  • View and print content for personal, non-commercial use
  • Share links to the Site

You may NOT:

  • Reproduce, distribute, modify, or create derivative works without written permission
  • Use any content for commercial purposes without a license
  • Remove copyright or proprietary notices
  • Use automated systems (bots, scrapers) to access the Site

Trademarks: "Nitap Technologies" and associated logos are trademarks of Nitap Technologies. Unauthorized use is prohibited.

8. Third-Party Links and Services

The Site may contain links to third-party websites or services (including Formspree, PostHog, LinkedIn, Credly). Nitap Technologies:

  • Does not control or endorse these third-party sites
  • Is not responsible for their content, privacy practices, or availability
  • Provides links for convenience only

You access third-party sites at your own risk and should review their terms and privacy policies.

9. Use of Insights and Articles

Articles in our "Insights" section represent the personal views, creative reflections, and analysis of the author (Dustyn Martin-Ross) and may draw on publicly available information, lived experience, and professional experience.

These articles:

  • Are opinion and analysis, not definitive fact
  • Do not necessarily reflect official positions of any organization
  • Should not be cited as authoritative sources without independent verification
  • May contain forward-looking statements that could prove incorrect

Indigenous Content: When discussing Indigenous communities, data sovereignty, or related topics, we strive for cultural sensitivity and accuracy. However, views expressed are the author's own and may not represent all Indigenous perspectives.

Indigenous Data in Engagements: In formal engagements with Indigenous community clients, we apply our Indigenous Data Sovereignty Framework and incorporate community-specific governance expectations to establish data stewardship commitments in writing.

Data governance, access, use, retention, and transfer are defined by the signed engagement terms, applicable laws, and community protocols. Our methodologies are designed to build internal capacity and transfer knowledge, not to create ongoing dependency or data asymmetry between the community and any outside party, including Nitap Technologies.

10. Contact Form and Communications

Submission of information through our contact form does not:

  • Create a client-consultant relationship
  • Establish confidentiality or privilege
  • Constitute a request for services
  • Obligate Nitap Technologies to respond or take any action

By submitting this form, you consent to Nitap Technologies contacting you regarding your specific inquiry. We will not add you to marketing lists without your express opt-in.

Do not submit confidential or sensitive information through the contact form. For confidential communications, contact us to establish a formal engagement with appropriate confidentiality protections.

10.1 Anti-Spam Compliance (CASL)

By submitting our contact form, you provide "implied consent" for Nitap Technologies to contact you regarding your specific inquiry. We will not use your contact information for unrelated marketing purposes or newsletters without your express, "opt-in" consent. You may withdraw consent at any time by contacting [email protected].

11. Changes to Terms

Nitap Technologies reserves the right to modify these Terms of Use at any time without prior notice. Changes are effective immediately upon posting. Your continued use of the Site after changes constitutes acceptance of the modified terms.

12. Dispute Resolution and Governing Law

Good-Faith Negotiation: Before initiating any formal legal proceeding, both parties agree to attempt to resolve any dispute through good-faith negotiation. Either party may initiate this process by providing written notice to the other describing the nature of the dispute and the relief sought. The parties shall have 30 days from the date of such notice to negotiate in good faith.

Mediation: If the dispute is not resolved through negotiation within 30 days, either party may refer the matter to non-binding mediation administered by a mutually agreed-upon mediator in Fredericton, New Brunswick, before pursuing litigation. The costs of mediation shall be shared equally unless otherwise agreed.

Governing Law: These Terms of Use are governed by the laws of the Province of New Brunswick and the federal laws of Canada applicable therein, without regard to conflict of law principles.

Jurisdiction: If a dispute is not resolved through negotiation or mediation, it shall be subject to the exclusive jurisdiction of the courts of New Brunswick, Canada.

13. Severability

If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.

14. Force Majeure

Nitap Technologies shall not be liable for any failure or delay in performance arising from causes beyond our reasonable control, including but not limited to acts of God, natural disasters, pandemic, war, terrorism, government restrictions, internet or telecommunications outages, cyberattacks on third-party infrastructure, or other events outside our reasonable control. Obligations affected by such events will be suspended for the duration of the event.

15. Waiver

No failure or delay by Nitap Technologies in exercising any right, remedy, or privilege under these Terms of Use shall operate as a waiver of that right, remedy, or privilege. A waiver of any breach or default shall not be treated as a waiver of any subsequent breach or default of the same or any other provision.

16. Entire Agreement

These Terms of Use, together with the Privacy Policy and any other legal notices published by Nitap Technologies on this Site, constitute the entire agreement between you and Nitap Technologies regarding your use of this Site. They supersede all prior agreements, representations, and understandings between you and Nitap Technologies relating to the subject matter herein.

Privacy Policy

Effective Date: June 22, 2026

1. Commitment to Privacy and Stewardship

Rooted in our value of stewardship, Nitap Technologies treats your personal information with the highest level of accountability and respect. This Privacy Policy explains how we collect, use, disclose, and safeguard your information in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.

Indigenous Data Governance: When engaged by or on behalf of First Nations, Métis, or Inuit communities, Nitap Technologies applies its Indigenous Data Sovereignty Framework and acknowledges OCAP® principles (Ownership, Control, Access, and Possession), as established by the First Nations Information Governance Centre (FNIGC), as a key reference point where relevant. In practice, this means:

  • Community Governance: Data governance for each engagement is defined collaboratively with the community and documented in formal engagement terms.
  • Purpose Limitation: Nitap Technologies does not repurpose or disclose community data outside the agreed scope without explicit, documented authorization.
  • Access and Stewardship: Access, stewardship responsibilities, and handling controls are established in writing to reflect community expectations and legal requirements.
  • Control in Practice: Where technically and operationally feasible, implementation approaches are selected to support community-directed control over data.

2. Information We Collect

2.1 Information You Provide Directly

Contact Forms: When you submit our contact form, we collect:

  • Name
  • Email address
  • Organization name (optional)
  • Message content

Purpose: To respond to your inquiries and provide requested information about our services.

Legal Basis: Consent (implied by form submission) and legitimate business interests.

2.2 Information Collected Automatically

Analytics Data: We use PostHog (EU) to understand how visitors interact with our Site. This may include:

  • Pages visited and time spent
  • Click patterns and scroll behaviour
  • Device type, browser, and screen resolution
  • General geographic location (city/region, not precise location)
  • Referral source (how you found our site)

Purpose: To improve user experience, optimize content, and understand visitor needs.

Data Type: Usage data including page views, click events, and interaction logs. PostHog EU processes all data within the European Union. We do not use this data to identify individual users. PostHog applies its own data handling practices as described in their privacy policy.

2.3 Information We Do NOT Collect

  • Payment information (we do not process payments through the Site)
  • Social insurance numbers or government IDs
  • Health information
  • Precise geolocation data
  • Biometric data

3. How We Use Your Information

We use collected information ONLY for the following purposes:

  • Responding to inquiries submitted through our contact form
  • Providing information about our services
  • Improving website functionality and user experience
  • Analyzing site traffic and visitor behaviour (anonymized)
  • Complying with legal obligations

We do NOT:

  • Sell or rent your personal information to third parties
  • Use your information for marketing without explicit consent
  • Share your information with third parties except as described in this policy

4. Third-Party Service Providers

We use trusted third-party services to operate our Site. These providers have access to your information only to perform specific tasks on our behalf and are obligated to protect it:

4.1 Formspree (Contact Form Processing)

  • Purpose: Manages contact form submissions and delivers inquiries to our email
  • Data Shared: Name, email, organization, message content
  • Privacy Policy: https://formspree.io/legal/privacy-policy/
  • Location: United States (data transferred outside Canada)

4.2 PostHog (Analytics)

  • Purpose: Provides website analytics, event tracking, and visitor behaviour insights
  • Data Shared: Page views, click events, and interaction data (see Section 2.2)
  • Privacy Policy: https://posthog.com/privacy
  • Location: European Union (EU region. Data does not leave the EU.)

4.3 Cloudflare (Web Hosting/CDN)

  • Purpose: Provides website hosting, security, and content delivery
  • Data Shared: IP addresses, request headers (technical data)
  • Privacy Policy: https://www.cloudflare.com/privacypolicy/
  • Location: Distributed globally with data centers including Canada

4.4 MailerLite (Email Newsletter)

  • Purpose: Delivers newsletter and article update emails to subscribers who opt in via the Insights page
  • Data Shared: Name (optional) and email address of newsletter subscribers
  • Privacy Policy: https://www.mailerlite.com/legal/privacy-policy
  • Location: United States (Some of its data processed under GDPR)

5. Data Retention

Contact Form Submissions: Retained for 24 months from last contact, or until you request deletion, whichever comes first.

Analytics Data: Retained by PostHog EU for up to 12 months, consistent with our account settings.

Right to Deletion: You may request deletion of your information at any time (see Section 9).

6. Data Security

We implement reasonable administrative, technical, and physical safeguards to protect your information from unauthorized access, disclosure, alteration, or destruction, including:

  • Encrypted data transmission (HTTPS/SSL)
  • Secure third-party service providers with appropriate security measures
  • Limited access to personal information (only personnel who need it)
  • Regular security reviews

However: No method of electronic transmission or storage is 100% secure. Nitap Technologies cannot ensure absolute security and is not liable for breaches resulting from causes beyond our reasonable control.

7. International Data Transfers

Our contact form provider (Formspree) transfers form submission data to the United States. PostHog processes analytics data exclusively within the European Union. By using our Site, you consent to data transfers as described. We ensure our service providers maintain appropriate safeguards for transferred data.

8. Cookies and Tracking Technologies

What Are Cookies: Small text files stored on your device by your web browser.

Cookies We Use:

  • Essential Cookies: Required for Site functionality (e.g., security, session management)
  • Analytics Cookies: PostHog cookies for traffic analysis and event tracking

Managing Cookies: You can control cookies through your browser settings. Note that disabling cookies may affect Site functionality.

Do Not Track and Global Privacy Control: Our Site responds to supported browser privacy signals, including "Do Not Track" and Global Privacy Control, by disabling analytics tracking when those signals are detected.

9. Your Privacy Rights

Under PIPEDA and applicable provincial laws, you have the right to:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your information (subject to legal retention requirements)
  • Withdraw Consent: Withdraw consent for collection, use, or disclosure of your information (may affect our ability to provide services)
  • Complaint: Lodge a complaint with the Office of the Privacy Commissioner of Canada if you believe we have violated your privacy rights

To Exercise Your Rights: Contact us at [email protected] with "Privacy Rights Request" in the subject line. We will respond within 30 days.

10. Children's Privacy

Our Site is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately.

11. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will post the updated policy on this page with a revised "Effective Date."

Material Changes: For significant changes affecting your rights, we will provide additional notice (e.g., email notification if we have your contact information).

12. Contact Information

For privacy-related questions, concerns, or rights requests:

Email: [email protected]
Subject Line: Privacy Inquiry
Mailing Address: Nitap Technologies, Fredericton, New Brunswick, Canada
Privacy Officer: Dustyn Martin-Ross, Principal Consultant

13. Data Breach Notification

In the event of a breach of security safeguards involving your personal information that poses a real risk of significant harm to you, Nitap Technologies will:

  • Notify you directly as soon as feasible after the breach is identified, in accordance with PIPEDA's breach of security safeguards requirements
  • Report the breach to the Office of the Privacy Commissioner of Canada
  • Maintain a record of all breaches involving personal information for a minimum of 24 months

Notifications will describe the nature of the breach, the personal information involved, steps Nitap Technologies has taken or will take to mitigate harm, and steps you may take to reduce your own risk. To report a suspected breach or vulnerability involving your data, contact [email protected] with "Data Breach" in the subject line.

Cookie Policy

Last Updated: February 8, 2026

What Are Cookies?

Cookies are small text files placed on your device when you visit a website. They help websites remember your preferences and understand how you use the site.

Cookies We Use

Cookie TypeProviderPurposeDuration
AnalyticsPostHog (EU)Track site usage, analyse visitor behaviour, and measure engagementSession + up to 12 months
SecurityCloudflareProtect against malicious activity, ensure site availabilitySession

Managing Your Cookie Preferences

Browser Settings: You can control or delete cookies through your browser:

  • Chrome: Settings → Privacy & Security → Cookies
  • Firefox: Settings → Privacy & Security → Cookies
  • Safari: Preferences → Privacy → Cookies
  • Edge: Settings → Cookies and Site Permissions

Impact of Disabling Cookies: The Site will still function, but analytics will not track your visit.

Third-Party Cookies

Our analytics provider (PostHog) may set cookies. We do not control these cookies. Review their privacy policy at posthog.com/privacy for more information.

Accessibility Statement

Last Updated: April 10, 2026

Nitap Technologies is committed to ensuring digital accessibility for people of all abilities. We strive to meet the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA standard and to align with the principles of the Accessible Canada Act (S.C. 2019, c. 10), which calls for a barrier-free Canada by January 1, 2040.

Applicable Standards

  • WCAG 2.1 Level AA: Our target conformance standard for web content
  • Accessible Canada Act (ACA): Federal framework guiding our approach to identifying and removing barriers

Current Accessibility Features

  • Semantic HTML structure with appropriate landmark regions
  • Alt text for meaningful images
  • Keyboard navigation support throughout the Site
  • Sufficient color contrast ratios for body text and interactive elements
  • Readable font sizes with support for browser-based text scaling
  • Mobile-responsive design
  • Skip-to-main-content navigation for screen reader and keyboard users

Known Limitations

We acknowledge the following areas where our Site may not yet fully meet WCAG 2.1 Level AA:

  • Some interactive components may not fully communicate state changes to assistive technologies
  • Third-party embedded content (e.g., external links, contact form) is subject to the accessibility practices of those providers

We are actively working to address these limitations. Our goal is to reach full WCAG 2.1 Level AA conformance by December 31, 2026.

Feedback and Assistance

If you encounter an accessibility barrier on our Site, please contact us:

Email: [email protected]
Subject Line: Accessibility

We will acknowledge your message within 5 business days and work to provide the requested information in an accessible alternative format, or address the barrier as quickly as practicable.